New in underway
api keys on screen, caught before you post
9 October 2026 · 3 min read
Post on Xthe short version
every screen in an underway episode is now read for api keys, tokens and passwords before the episode can go anywhere.
if something on your screen looks like a key, the episode page says what it looked like and where: "what looked like an anthropic api key, sk-a…, 1h 12m into the session." you answer it in one press. take the screen off there, or it's fine. until you do, the episode stays off your page, off youtube, off every network and out of your shorts.
why this exists
the best build-in-public footage is the work itself: the terminal, the editor, the dashboard, an ai agent writing code. it is also exactly where keys show up. an env file opened for a second. a curl command with a bearer token in it. a settings page that shows the full key once, right after you make it.
a key on screen for a second is a key anyone can pause on. watching four hours back to check is not a real answer, and nobody does it. so the check happens for you, every time the file is made.
how it works
- when your episode's file is made, every screen in it is read: screens you shared in an answer, a walk-through, and the hours of watch me work
- only the frames where the screen changed are read, so hours cost minutes
- the text read off each frame is checked for the shapes keys have: anthropic, openai, stripe, github, aws, google, slack, supabase tokens and more, plus lines like api_key= followed by something random
- each candidate is looked at again from a frame of it, so a placeholder like your-api-key-here, a masked value or a variable's name is not called a key
- what is left holds the episode, and the top of the episode page lists each one
your two answers
take the screen off there keeps you on camera for that stretch instead of the screen, or skips that stretch of watch me work, and makes the file again without it. nothing else about the episode changes.
it's fine releases it. use it when the check was wrong, or when the key was already deleted.
if it was a real key that was live, change it at the service it came from as well. taking it out of the video stops it spreading; it does not undo anyone who already saw it.
what it never keeps
the key itself is never stored. underway keeps what kind of key it looked like, its first four characters and how long it was, enough for you to know which one, never enough to use it.
nothing slips past
every way an episode leaves underway checks the hold: your page, the automatic listing on a public series, youtube, tiktok, instagram, linkedin, x, your shorts and the daily posting. a short made before you took the screen off is made again before it can post, because it still has the screen in it.
and a check that could not finish is not a pass. if it runs out of time or breaks, the episode is held as not checked, and the page asks you to look yourself.
how do i stop api keys showing in my screen recordings?
box what people may see before you share, so the rest of the window is destroyed before it is recorded, and let underway read every screen for keys before anything goes out. anything that looks like a key holds the episode until you answer it.
does underway store the key it finds?
no. only what kind of key it looked like, its first four characters and its length.
what if it flags something that isn't a key?
press it's fine and the episode is released. every candidate is looked at twice first, so placeholders and masked values are rarely flagged.
start a series and film episode zero for free. start free.